LinkedIn analytics tracking pixel for AIDOLS AI consulting website performance measurement
Governance & Risk

Fundamental Rights Impact Assessment (FRIA)

A Fundamental Rights Impact Assessment (FRIA) is the structured analysis required by Article 27 of the EU AI Act for certain deployers of high-risk AI systems — bodies governed by public law, private operators of public services, and deployers of credit-scoring or insurance-pricing AI.

Full definition

Required content includes: (1) processes in which the system will be used; (2) period and frequency of use; (3) categories of natural persons likely affected; (4) specific risks of harm; (5) human-oversight measures; (6) mitigations if risks materialize. The assessment must be notified to the relevant market-surveillance authority. FRIA is distinct from — and complementary to — GDPR Data Protection Impact Assessment (DPIA); the AI Act allows the two to be combined.

Why it matters

FRIA puts deployers (not just providers) on the hook for high-risk AI governance. For public-sector buyers and regulated industries, FRIA is now a mandatory step in any procurement of high-risk AI — and a recurring compliance cost.

Example

A municipality deploys an AI tool to triage social-benefits applications (Annex III §5); before go-live it runs a FRIA covering language access, appeal rights, and disparate-impact monitoring, and registers the assessment with the national authority.

Source & further reading

Primary source: European Union — Regulation (EU) 2024/1689, Article 27 (2024).

Citation policy: this entry is part of the AIDOLS AI Implementation Glossary and may be quoted for research, journalism, and education with attribution to aidolsgroup.com/fr/glossary/fundamental-rights-impact-assessment/.